Junglewise Threat Intelligence

CVE-2026-44682: Acronis DeviceLock DLP local privilege escalation via DLL hijacking

CVE-2026-44682 · Severity: high · CVSS 7.3 · Published 2026-06-03

Technologies: Acronis DeviceLock DLP. Vendors: Acronis.

Executive brief

Acronis DeviceLock DLP, a security solution used to prevent data leaks on corporate endpoints, is vulnerable to a local privilege escalation flaw. An attacker who already has limited access to a computer could exploit this to gain full administrative control by tricking the system into loading a malicious file. This could allow an unauthorized user to bypass security controls, access sensitive data, or disable the protection software entirely.

Technical details

A local privilege escalation vulnerability exists in Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227 due to an uncontrolled search path element (CWE-427), commonly known as DLL hijacking. The application fails to properly validate or restrict the paths from which it loads dynamic link libraries (DLLs). A local attacker with low-level privileges can exploit this by placing a malicious DLL file in a location searched by the application before the legitimate library. When a user with higher privileges or the system itself triggers the application, the malicious code is executed, granting the attacker elevated permissions (High Confidentiality, Integrity, and Availability impact). User interaction is required to trigger the execution.

Affected products

  • Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory

References

Related threats